fix: harden thothctl Windows safe I/O

This commit is contained in:
2026-08-04 17:55:36 +02:00
parent f5468f0d36
commit c90299f24d
9 changed files with 175 additions and 32 deletions
@@ -10,11 +10,15 @@ import (
"golang.org/x/sys/windows"
)
const windowsRetainedHandleShareMode uint32 = windows.FILE_SHARE_READ | windows.FILE_SHARE_WRITE
// ReadCanonicalRegular opens each component with FILE_FLAG_OPEN_REPARSE_POINT and rejects a
// reparse point on the opened handle before opening the next component. Windows' Win32 API does
// not expose a portable descriptor-relative equivalent of POSIX openat, so a hostile local actor
// with permission to rename a normal parent between these opens remains outside this guarantee.
// Installation directories therefore need trusted local filesystem/ACL ownership on Windows.
// reparse point on the opened handle before opening the next component. Retained handles allow
// ordinary read/write sharing but deny delete sharing, which blocks rename or deletion after a
// component is opened and throughout the final read. Windows' Win32 API does not expose a
// portable descriptor-relative equivalent of POSIX openat, so a hostile local actor can still
// replace a not-yet-opened normal component between absolute-path opens. Installation directories
// therefore need trusted local filesystem/ACL ownership on Windows.
func ReadCanonicalRegular(path string, maximum int64) ([]byte, error) {
if err := ValidateCanonicalPath(path); err != nil {
return nil, err
@@ -62,7 +66,7 @@ func openWindowsComponent(path string, directory bool) (windows.Handle, error) {
handle, err := windows.CreateFile(
windows.StringToUTF16Ptr(path),
windows.GENERIC_READ,
windows.FILE_SHARE_READ|windows.FILE_SHARE_WRITE|windows.FILE_SHARE_DELETE,
windowsRetainedHandleShareMode,
nil,
windows.OPEN_EXISTING,
flags,